Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel 5.10版本至7.2-rc1之前版本存在安全漏洞,该漏洞源于jbd2_journal_initialize_fast_commit()函数在验证日志容量时存在整数下溢问题,当num_fc_blks超过j_last时,减法运算回绕绕过边界检查,导致日志中止。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 6866d7b3f2bb4f011041ba54c98b1584497fe2fd< aa90f00932bf572d6ef284c977c2a60b39c13bd6 |
affected |
6866d7b3f2bb4f011041ba54c98b1584497fe2fd< e144ad0250f77e23e28949587b8b57e40dc3b512 |
affected | ||
6866d7b3f2bb4f011041ba54c98b1584497fe2fd< 4b48dcb88bb9117e3d3f051175a9a8b7cff7f8b6 |
affected | ||
6866d7b3f2bb4f011041ba54c98b1584497fe2fd< fb9b49618ed7296ebfad62a3835da8945f727001 |
affected | ||
6866d7b3f2bb4f011041ba54c98b1584497fe2fd< 4450dcaadf7d4aae8b6e4223b5d6ee4eb77097a9 |
affected | ||
6866d7b3f2bb4f011041ba54c98b1584497fe2fd< 78955fdce8ff654e6d33a2fa90882a1e7eb26330 |
affected | ||
6866d7b3f2bb4f011041ba54c98b1584497fe2fd< a58fc10adf503969fec2007b5afe8987258046c4 |
affected | ||
6866d7b3f2bb4f011041ba54c98b1584497fe2fd< 289a2ca0c9b7eae74f93fc213b0b971669b8683d |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72407 | 10.0 CRITICAL | geneve: validate inner network offset in geneve_gro_complete() |
| CVE-2026-72408 | 10.0 CRITICAL | geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint |
| CVE-2026-74475 | 10.0 CRITICAL | vxlan: use neigh_ha_snapshot() in route_shortcircuit() |
| CVE-2026-74279 | 10.0 CRITICAL | crypto: cavium/cpt - fix DMA cleanup using wrong loop index |
| CVE-2026-74280 | 10.0 CRITICAL | crypto: marvell/octeontx - fix DMA cleanup using wrong loop index |
| CVE-2026-72421 | 10.0 CRITICAL | ipv4: fib: Don't ignore error route in local/main tables. |
| CVE-2026-74309 | 10.0 CRITICAL | vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler |
| CVE-2026-72493 | 9.9 CRITICAL | net: serialize netif_running() check in enqueue_to_backlog() |
| CVE-2026-74376 | 9.8 CRITICAL | md/raid10: reset read_slot when reusing r10bio for discard |
| CVE-2026-74433 | 9.8 CRITICAL | rxrpc: Fix UAF in rxgk_issue_challenge() |
| CVE-2026-74434 | 9.8 CRITICAL | rxrpc: Don't move a peeked OOB message onto the pending queue |
| CVE-2026-72191 | 9.8 CRITICAL | ntfs3: validate split-point offset in indx_insert_into_buffer |
| CVE-2026-72299 | 9.8 CRITICAL | tipc: restrict socket queue dumps in enqueue tracepoints |
| CVE-2026-72398 | 9.8 CRITICAL | sctp: add INIT verification after cookie unpacking |
| CVE-2026-74384 | 9.8 CRITICAL | nvme-multipath: fix flex array size in struct nvme_ns_head |
| CVE-2026-72442 | 9.8 CRITICAL | netfilter: flowtable: fix and simplify IP6IP6 tunnel handling |
| CVE-2026-74436 | 9.8 CRITICAL | rxrpc: serialize kernel accept preallocation with socket teardown |
| CVE-2026-74545 | 9.8 CRITICAL | rtase: fix double free of multi-frag skb on DMA map failure |
| CVE-2026-72046 | 9.8 CRITICAL | gve: fix header buffer corruption with header-split and HW-GRO |
| CVE-2026-72473 | 9.8 CRITICAL | xprtrdma: Decouple req recycling from RPC completion |
Showing top 20 of 845 CVEs. View all on vendor page → →
No comments yet